Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
How not to respond to a security advisory
Jason Miller, 2006-01-18

A recently announced weakness in the BSD securelevel system isn't going to be fixed in OpenBSD. While securelevel may have problems, the vendor's security response is unacceptable and doesn't fit with their stated goals.

Submit Comment Mode:
Name:
Subject:
Message:
 
  Enter the characters that appear above
 
Re: How not to respond to a security advisory 2006-01-19
Dwight
It really doesnt matter why Theo said it. For argument sake, even if Theo is fully correct, then it doesnt make sense to give users a "security" feature you know is broken. In his response he says its useless and doesnt provide security, in the OpenBSD man page it says it provides security. Which is...

[ more ]  





 

Privacy Statement
Copyright 2009, SecurityFocus